Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a9fb3b9468f6790…

MALICIOUS

PDF

81.3 KB Created: 2009-07-17 18:58:01 Authoring application: Scribus 1.3.3.13 (via Scribus PDF Library 1.3.3.13)
MD5: 2ef82d8320c89ba7480a6b7541064b45 SHA-1: 060858e560920fe84c6463e9bd36b00434d6560d SHA-256: 0a9fb3b9468f679046ef0c172f4c3b2c366151581a3710501781b30b8f2ebeb6
110 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

The PDF file contains embedded JavaScript, flagged by multiple heuristics, indicating malicious intent. The JavaScript is heavily obfuscated but appears to be designed to download and execute a second-stage payload. The ML classifier and ClamAV detection strongly support this assessment, classifying it as a dropper.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Dropper.Agent-5676975-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-5676975-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 1 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xap/1.0/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/photoshop/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/tiff/1.0/
    • http://ns.adobe.com/exif/1.0/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0015_000.js
d14f3782280049970f4a07440f807ce5b5fb813a83e40f7c4f3d2bf7dda9fc3d
pdf-javascript-stream PDF /JS object 15 at offset 0x115FE 44585 bytes
javascript_obj0016_001.js
f22049e229e85fad53da2d311278cfe9082de589f79cafe666f8509bcc752f34
pdf-javascript-stream PDF /JS object 16 at offset 0x13F24 276 bytes
javascript_obj0017_002.js
143cc6ba40bcc00058d21bcf2dbb83982267341d54e179cc67e1fabdeea672d8
pdf-javascript-stream PDF /JS object 17 at offset 0x1404B 242 bytes